Executive brief
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
Affected products
- PyPI cryptography
Junglewise Threat Intelligence
CVE-2016-9243 · Severity: low · CVSS 3 · Published 2017-03-27
Technologies: cryptography (PyPI). Vendors: PyPI.
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.